CVE-2026-23617 | GFI MailEssentials AI up to 22.3 Management Interface ASKeywordChecking.aspx ctl00$ContentPlaceHolder1$pvGeneral$TXB_Condition cross site scripting
A vulnerability described as problematic has been identified in GFI MailEssentials AI up to 22.3. This issue affects some unknown processing of the file /MailEssentials/pages/MailSecurity/ASKeywordChecking.aspx of the component Management Interface. Such manipulation of the argument ctl00$ContentPlaceHolder1$pvGeneral$TXB_Condition leads to cross site scripting.
This vulnerability is listed as CVE-2026-23617. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.